Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-348g-w65w-cxjq

4 месяца назад

Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively large string. Attackers can generate a file containing a massive buffer of repeated characters and paste it into the unavailable value field in the display preferences to trigger a denial of service.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-348g-w2wh-vvq4

больше 4 лет назад

Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.

EPSS: Низкий
github логотип

GHSA-348g-pv2q-pj9p

8 месяцев назад

In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-348g-3f7x-jvgj

больше 4 лет назад

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-348f-xf8c-h3v7

12 месяцев назад

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_base_set in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-348f-gwqg-3m3w

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-348c-hvj3-g7hp

больше 4 лет назад

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

EPSS: Низкий
github логотип

GHSA-3489-8qg3-xgj4

около 4 лет назад

This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

EPSS: Низкий
github логотип

GHSA-3487-3j7c-7gwj

больше 2 лет назад

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3486-w28q-g6jc

больше 4 лет назад

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

EPSS: Низкий
github логотип

GHSA-3486-rvxc-hrrj

около 4 лет назад

gitblame susceptible to command injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3486-2953-r9fc

7 месяцев назад

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3485-7x7c-qrw2

почти 4 года назад

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3485-35jp-jwmx

около 3 лет назад

axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3484-rr8g-54gq

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3484-2rvh-885x

больше 2 лет назад

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-19724.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3483-fv4j-8x97

около 4 лет назад

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

EPSS: Низкий
github логотип

GHSA-3483-cg54-gpx2

2 месяца назад

Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3483-88xw-5g3h

больше 1 года назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3483-6grv-x2wh

около 4 лет назад

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-348g-w65w-cxjq

Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively large string. Attackers can generate a file containing a massive buffer of repeated characters and paste it into the unavailable value field in the display preferences to trigger a denial of service.

CVSS3: 6.2
0%
Низкий
4 месяца назад
github логотип
GHSA-348g-w2wh-vvq4

Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-348g-pv2q-pj9p

In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-348g-3f7x-jvgj

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-348f-xf8c-h3v7

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_base_set in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-348f-gwqg-3m3w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-348c-hvj3-g7hp

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3489-8qg3-xgj4

This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3487-3j7c-7gwj

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3486-w28q-g6jc

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3486-rvxc-hrrj

gitblame susceptible to command injection

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3486-2953-r9fc

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVSS3: 8.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-3485-7x7c-qrw2

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3485-35jp-jwmx

axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3484-rr8g-54gq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3484-2rvh-885x

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-19724.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3483-fv4j-8x97

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3483-cg54-gpx2

Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3483-88xw-5g3h

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3483-6grv-x2wh

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу